Skip to content

Maintenance: CI modernization, CVE/secret scan (clean) - #2

Merged
weisser-dev merged 1 commit into
mainfrom
maintenance/cve-and-checks
Oct 3, 2026
Merged

weisser-dev merged 1 commit into
mainfrom
maintenance/cve-and-checks

Conversation

@weisser-dev

@weisser-dev weisser-dev commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

Maintenance pass: security scan, functional checks, CI modernization.

Trivy fs (vuln+secret, HIGH/CRITICAL) and npm audit: 0 findings before and after. No dependency changes: no CVEs exist, and the latest majors (chalk 6 needs Node >=22, ora 9 / inquirer 8 need >=20) would raise the engine floor for users without a security benefit, so they were deliberately not applied. Lockfile is committed and up to date.

Changes

  • ci.yml: actions/checkout v7, setup-node v7, permissions: contents: read, concurrency, Node matrix 20/22/24, npm cache.
  • release.yml: actions v7/v7, softprops/action-gh-release v3, workflow input passed via env instead of direct ${{ }} interpolation in shell.

Checked

  • 87/87 tests pass (Node 20), npm pack --dry-run OK, CLI --help and start in an empty temp HOME writes nothing.
  • 108 agents / 15 skills: front matter present, skills name == dir, configs valid JSON, templates in sync.
  • Secret grep on HEAD and full history: no real secrets.
  • README links: all reachable (non-200 only for MCP endpoints/example URLs).

…x, avoid expression injection in release

Trivy (vuln+secret, HIGH/CRITICAL) and npm audit: 0 findings before and after.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XNi42F9voFf5YMVC5xbsk7
@weisser-dev
weisser-dev merged commit 9d54ac9 into main Oct 3, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant